{"id":13478,"date":"2026-06-09T10:03:38","date_gmt":"2026-06-09T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/09\/threat-actors-abuse-chatgpt-claude-and-deepseek-brands-as-phishing-lures-to-steal-credentials\/"},"modified":"2026-06-09T10:03:38","modified_gmt":"2026-06-09T10:03:38","slug":"threat-actors-abuse-chatgpt-claude-and-deepseek-brands-as-phishing-lures-to-steal-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/09\/threat-actors-abuse-chatgpt-claude-and-deepseek-brands-as-phishing-lures-to-steal-credentials\/","title":{"rendered":"Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials"},"content":{"rendered":"<p>    Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Cybercriminals have found a clever new trick: turning the world\u2019s most popular AI tools into traps. By disguising phishing attacks with the branding of platforms like ChatGPT, Claude, and DeepSeek, threat actors are luring users into handing over login credentials, credit card numbers, and authentication tokens.<\/p>\n<p class=\"wp-block-paragraph\">The surge in AI adoption has given attackers fertile ground to exploit. Millions of people now rely on AI assistants daily, and many are still learning what legitimate communications from these platforms look like. <\/p>\n<p class=\"wp-block-paragraph\">This creates the perfect window for fraud. Attackers dress up a fake page or email to resemble a trusted AI platform, and a significant number of people click without a second thought.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Threat Intelligence analysts identified and documented several of these campaigns that unfolded in early 2026. <\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/06\/08\/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering\/\" id=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/06\/08\/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft said in a report<\/a> shared with\u00a0Cyber Security News (CSN)\u00a0that these campaigns do not represent any actual breach of the AI services themselves. <\/p>\n<p class=\"wp-block-paragraph\">They are pure social engineering operations that borrow trusted brand names to push users into clicking a link, opening a PDF, or downloading a file.<\/p>\n<p class=\"wp-block-paragraph\">What makes these attacks harder to stop is that attackers route victims through real, trusted services before reaching the malicious destination. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhvr3F1d5I2FX4lWscqvm_nnsBIjay_85G53kxXXv9bqBC_oOTD1QYXqDteHQYF7i7QZCL-WDChEuFOuRrLWplNPFqePwadi5aXHP9qq9LLymCp5pXdUScBc5pn_HMW_jDO43DLZpL6m8PATBLXXYq6P9IgkWscJD1kZI2dRm7lA7xAEqVxUJp8wWl95Ic\/s16000\/Attack%2520chain%2520of%2520ChatGPT-themed%2520lure%2520leading%2520to%2520phishing%2520kit%2520%28Source%2520-%2520Microsoft%29.webp?ssl=1\" alt=\"Attack chain of ChatGPT-themed lure leading to phishing kit (Source - Microsoft)\"><figcaption class=\"wp-element-caption\">Attack chain of ChatGPT-themed lure leading to phishing kit (Source \u2013 Microsoft)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Platforms like URL shorteners, CRM tools, and GitHub are layered into the chain to avoid detection. By the time someone realizes something is wrong, their information may already be gone.<\/p>\n<p class=\"wp-block-paragraph\">The consequences are serious, as thousands of organizations across multiple countries have been targeted, with victims losing credit card data, account access, and <a href=\"https:\/\/cybersecuritynews.com\/salesloft-drift-customer-authentication-tokens\/\" id=\"123931\" target=\"_blank\" rel=\"noreferrer noopener\">authentication tokens that hand attackers a direct entry point<\/a> into corporate systems.<\/p>\n<h2 id=\"h-threat-actors-abuse-chatgpt-claude-and-deepseek-brands\" class=\"wp-block-heading\"><strong>Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The ChatGPT-themed campaign detected on May 5, 2026 shows how this works in practice. <\/p>\n<p class=\"wp-block-paragraph\">Attackers sent around 4,500 emails to targets in South Africa, warning that their ChatGPT Plus subscription would be downgraded unless they updated their payment method within seven days. <\/p>\n<p class=\"wp-block-paragraph\">The emails carried the ChatGPT logo and a clickable update button that looked entirely legitimate.<\/p>\n<p class=\"wp-block-paragraph\">That button did not send users directly to a malicious site. Victims were bounced through a CRM service, an Amazon tracking domain, and a URL shortener before landing on a compromised website where a fake payment page sat inside a subfolder. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiq6tt7MoEksJjKDjCtrnR_-8UI_VSscquKK7BeHG3mN64WkE9aIGowYzsl1eA0N8BW0TZjUWclB6TXdJmwLgKmCmHfeLkICn12uhg1adyQ13Dfwdx_ZwtSXMEG3wtUjwNS3xRCpj1L3nHM6izpw76AktF5QamG4isDb17n3MJn6fnmTX5CDuVyUS_9uhk\/s16000\/Phishing%2520landing%2520page%2520collecting%2520name%2520and%2520address%2520%28Source%2520-%2520Microsoft%29.webp?ssl=1\" alt=\"Phishing landing page collecting name and address (Source - Microsoft)\"><figcaption class=\"wp-element-caption\">Phishing landing page collecting name and address (Source \u2013 Microsoft)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The page showed a <a href=\"https:\/\/cybersecuritynews.com\/fake-captcha-delivers-eddiestealer\/\" id=\"109164\" target=\"_blank\" rel=\"noreferrer noopener\">fake CAPTCHA to filter automated scanners, then collected personal details<\/a> and full credit card information across two steps.<\/p>\n<p class=\"wp-block-paragraph\">The Claude-themed campaign ran from April 20 to 22, 2026, reaching more than 2,000 organizations in the United States, the United Kingdom, and India. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjdZlDhUuO9S4Lp3XiC52adLL4_nR8TGsNkIv1-Yz-LXfrYbUfwvD8hs5IctEJVrDTOIkTx9frPtGriRR7EqkmGcrgQUw_91hrX8_qwfo3FLrYprdBtkcX3tZMrcOsNqKXQ__hfto343dpPhD5309IIt5hfD5Xrwl3Rh3FmUc3t6_wczlonlW2KVKFbTyg\/s16000\/Attack%2520chain%2520of%2520Claude-themed%2520phishing%2520campaign%2520leading%2520to%2520AiTM%2520%28Source%2520-%2520Microsoft%29.webp?ssl=1\" alt=\"Attack chain of Claude-themed phishing campaign leading to AiTM (Source - Microsoft)\"><figcaption class=\"wp-element-caption\">Attack chain of Claude-themed phishing campaign leading to AiTM (Source \u2013 Microsoft)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Emails claimed the recipient\u2019s account had violated usage policies, with a PDF named \u201cFill and Sign Claude Appeal Form.pdf\u201d directing users to an attacker-controlled domain. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhjzn16rRG5BoeRHu9D2bHz2YpZMDMBEaB0Xuo2cDqgV_hAk6iaCZhN5bT-b2ZoSOIVvVt7kINIcvF5TuZZFwad3Fzpj68qZztCY2WbDNqBmJSlnSED4BMi4RT7zVCzc5Ok2UpZ5rqpFQL_lG8QQFDGJtNwgH2Mn0gBq7WDG4KbyhXEFFk3o-t4FD89FK0\/s16000\/Attack%2520chain%2520for%2520%25E2%2580%259CAwesome%2520AI%2520Windows%2520plugin%25E2%2580%259D%2520malvertising%2520leading%2520to%2520Vidar%2520%28Source%2520-%2520Microsoft%29.webp?ssl=1\" alt=\"Attack chain for \u201cAwesome AI Windows plugin\u201d malvertising leading to Vidar (Source - Microsoft)\"><figcaption class=\"wp-element-caption\">Attack chain for \u201cAwesome AI Windows plugin\u201d malvertising leading to Vidar (Source \u2013 Microsoft)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Victims were pushed through fake verification screens before being redirected toward what appeared to be a Microsoft sign-in page designed to steal access tokens.<\/p>\n<h2 id=\"h-fake-deepseek-installer-and-malvertising-drop-vidar\" class=\"wp-block-heading\"><strong>Fake DeepSeek Installer and Malvertising Drop Vidar<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">In April 2026, attackers moved fast after DeepSeek previewed its V4 model. <\/p>\n<p class=\"wp-block-paragraph\">Within 45 minutes, a fake GitHub organization called DeepSeek-V4 was live, loaded with stolen branding, real benchmark data, and search-optimized tags designed to rank high in both traditional and AI-assisted search results. <\/p>\n<p class=\"wp-block-paragraph\">Users who downloaded the archives received a loader that silently installed Vidar infostealer on their devices.<\/p>\n<p class=\"wp-block-paragraph\">A <a href=\"https:\/\/cybersecuritynews.com\/new-malvertising-campaign\/\" id=\"125968\" target=\"_blank\" rel=\"noreferrer noopener\">separate malvertising campaign linked to Storm-3075<\/a> pushed a fake product called \u201cAwesome AI Windows Plugin\u201d through free movie streaming sites. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjgFwfZVxvYSfzBrbDxFvgYZMCGGw3EBeIOh_YtqNo7sBA3WEYS65IkNj2Ica-T7LI04OPSK8eG_h2BH1E6Y6uMBo_XyPPn0LtqRFxJPZc35IYTM8rJCjFuVtUmSRnKxIOahVNFO_9nYNOCE8nN_5tvDxJbDUqV72LvwStgPTu0dHYC-2XgNxE_zdUa27A\/s16000\/Fake%2520DeepSeek%2520V4%2520campaign%2520timeline%2520and%2520attack%2520chain%2520%28Source%2520-%2520Microsoft%29.webp?ssl=1\" alt=\"Fake DeepSeek V4 campaign timeline and attack chain (Source - Microsoft)\"><figcaption class=\"wp-element-caption\">Fake DeepSeek V4 campaign timeline and attack chain (Source \u2013 Microsoft)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The download was a fraudulently code-signed executable tied to Fox Tempest, a group running a malware-signing service used by multiple criminal actors. <\/p>\n<p class=\"wp-block-paragraph\">Once users launched the file and clicked a \u201cContinue\u201d prompt, a Python downloader quietly fetched Vidar from an attacker-controlled server.<\/p>\n<p class=\"wp-block-paragraph\">To reduce exposure, users and organizations should enable multi-factor authentication on all accounts and avoid clicking links or downloading files from unsolicited emails. <\/p>\n<p class=\"wp-block-paragraph\">AI platform communications should always be verified by visiting the official website directly. Organizations should also deploy email link scanning tools and solutions that detect and block phishing pages before users ever reach the malicious content.<\/p>\n<p class=\"wp-block-paragraph\" id=\"h-indicators-of-compromise-iocs\"><strong>Indicators of Compromise (IoCs):-<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Indicator<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>SHA-256<\/td>\n<td>791efb555eefb7215e96659a1353a97416743b66bdd72705493129c64057d40e<\/td>\n<td>File hash for attachment: Fill and Sign Claude Appeal Form.pdf<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>hxxp:\/\/dash.awaydouble[.]org\/0v2auth<\/td>\n<td>URL inside the Claude phishing PDF attachment<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>hxxps:\/\/github[.]com\/shippingtechnologymovie\/AI-techVideos\/releases\/download\/13123\/ProFluxeFlowAi-win-Setup.exe<\/td>\n<td>Fraudulent GitHub repository (taken down) hosting malware executable<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>c7c5072df9f83f4c440a5c3bb4be1d5f6c67bbf78f196406ca20d27b43b975b8<\/td>\n<td>File hash for ProFluxeFlowAi-win-Setup.exe<\/td>\n<\/tr>\n<tr>\n<td>Signer SHA-1<\/td>\n<td>4f5c5b3ef45cfff7721754487a86aeff9a2e6e32<\/td>\n<td>Fraudulent code-signing certificate (Fox Tempest)<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>brokeapt[.]com<\/td>\n<td>Attacker-controlled C2 domain for Python loader<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>pan.ssffaa19[.]xyz<\/td>\n<td>Vidar C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>pan.rongtv[.]xyz<\/td>\n<td>Vidar C2 domain<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>hxxps:\/\/github[.]com\/DeepSeek-V4\/deepseek-V4\/releases\/download\/deepseek-V4\/deepseek-v4-pro_x64.7z<\/td>\n<td>Fraudulent DeepSeek GitHub repository (taken down)<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>0a26238f6c516de5885457c93042531aa59bc206a9537cebf5267cedc6c68531<\/td>\n<td>deepseek-v4-pro_x64.7z (v1)<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>8610d4fb0ec5b525071c2aaec4df0f8fcbb3673aba58a7e1959fc44e83c0e2ca<\/td>\n<td>deepseek-v4-flash_x64.7z (v1)<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>99231deb373997364381d1eb513d2d42231d418c3a2db9007c5af9bd56ab9371<\/td>\n<td>deepseek-v4-flash_x64.7z (v2)<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>25270cc429ada8028b5b33220ed412c47907ecceea7377d608fac5af01bed56a<\/td>\n<td>deepseek-v4-pro_x64.7z (v2)<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>56d722b0331bf0aaa86bb37483486c6dff6ad9427fc473ed7c3226c21a9bdd23<\/td>\n<td>DeepSeek-specific extracted PE (deepseek-v4-pro_x64.exe, deepseek-v4-flash_x64.exe, VectorEngine.exe)<\/td>\n<\/tr>\n<tr>\n<td>SHA-256<\/td>\n<td>5455341ed1bbe75a664fca2dd0794c508e1874f75360253a7ff5bc119bc92d80<\/td>\n<td>Shared loader observed under multiple AI-brand lure names<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong>\u00a0<em>IP addresses and domains are intentionally defanged (e.g.,\u00a0<\/em><code><em>[.]<\/em><\/code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM<\/em>.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong> <strong><strong><a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a><\/strong><\/strong>.<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-abuse-chatgpt-claude-and-deepseek-brands-as-phishing-lures\/\">Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-abuse-chatgpt-claude-and-deepseek-brands-as-phishing-lures\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands as Phishing Lures to Steal Credentials Cybercriminals have found a clever new trick: turning the world\u2019s most popular AI tools into traps. By disguising phishing attacks with the branding of platforms like ChatGPT, Claude, and DeepSeek, threat actors are luring users into handing over login credentials, credit [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-13478","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13478"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13478"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13478\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13478"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13478"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13478"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}